EH-Net

Resources => News from the Outside World => Topic started by: don on December 09, 2005, 11:57:50 AM



Title: Mozilla Downplays Firefox 1.5 Exploit
Post by: don on December 09, 2005, 11:57:50 AM
A private security outfit has released a proof-of-concept exploit for a security flaw in Firefox 1.5, warning that the code can be modified to launch code execution attacks.

However, officials at the Mozilla Foundation are downplaying the threat, insisting the bug is more of an "annoyance" than a serious security vulnerability.

The exploit, which was posted on the PacketStormSecurity.org Web site, targets a buffer overflow in Firefox 1.5, the newest browser release from Mozilla.

The exploit has been confirmed on Firefox 1.5 on Windows XP SP2 (Service Pack 2) and is caused by an error in the way the open-source browser handles large history information.

A successful attacker can fill the browser's "history.dat" file with large history information by tricking a user into visiting a malicious Web site with an overly large title.

For full story:
http://www.eweek.com/article2/0,1895,1898253,00.asp

Don